Orval code generator can run attacker JavaScript on import

Published September 3, 2026 CVE-2026-71868

A bug in the Orval code-generation tool lets an attacker sneak live JavaScript into an API description file. If a developer runs Orval on that file, the malicious code runs automatically the moment the generated code is loaded, no extra step needed.

Severity
CriticalCVSS 4.0 · 9.3
Fix
Fixed in 8.21.0Fix recorded on Sep 3, 2026
Affected versions
before 8.21.0
Weakness
CWE-94Code Injection
Exploit likelihood
0.61% in 30 daysEPSS, higher than 47% of known flaws
Affects
Orval+2 more

How it works

Orval writes an API field's default value straight into the generated code as a template string, and it does not strip out special JavaScript syntax like backticks or dollar-curly-brace expressions, so a rigged default value becomes code that runs when the generated file is opened.

What to do

Run npm ls orval in your project to see the installed version, and compare it against 8.21.0. If you generate zod schemas with enum fields that have defaults, and the spec source is not fully trusted, you are exposed.

Run this in the application environment you want to check:

npm ls orval

Update to Orval 8.21.0 or later with npm install orval@latest, and until you update, avoid generating code from OpenAPI specs you did not write yourself or fully vet.

Technical details

Affected software: Orval, npm, zod

Orval's zod schema generator (packages/zod/src/index.ts, function formatDefaultValue) writes an enum's default value into a module-level JavaScript template literal without encoding backticks or ${...} sequences. A spec author can set a default like v${globalThis.someFunc}w, and Orval emits that string unescaped into the generated file. Because ${...} inside a template literal is live JavaScript, the expression executes the instant the generated module is imported, no function call required.

This gives CWE-94/CWE-1336 style code injection at import time in any developer, CI, test, or application environment that loads the generated schema. Fixed in 8.21.0 by properly encoding default values.

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low No extra steps to bypass built-in attack protections
  • Required conditions None No particular deployment or execution condition is required
  • Privileges required None Attacker needs no account or login
  • User action None No action by another user is required
  • Vulnerable system: Data exposure High Sensitive data can be exposed with serious impact
  • Vulnerable system: Data changes High Protected data can be changed with serious impact
  • Vulnerable system: Service disruption High The service can stop or suffer serious disruption
  • Other systems: Data exposure None No additional impact beyond the vulnerable system
  • Other systems: Data changes None No additional impact beyond the vulnerable system
  • Other systems: Service disruption None No additional impact beyond the vulnerable system
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Open in FIRST.org calculator

References